DEV Community

Charles
Charles

Posted on

5 Things Every Developer Should Know About Web Scraping API Keys

5 Things Every Developer Should Know About Web Scraping API Keys

Don't leak your keys. Lessons from experience.

1. Never Hardcode

// BAD
const key = "xc-..."
// GOOD
const key = process.env.XCRAWL_API_KEY;
Enter fullscreen mode Exit fullscreen mode

2. Use .env Files

Add to .gitignore immediately.

3. Rotate Monthly

Generate new key, revoke old one. Keep a lifecycle log.

4. Separate per Environment

dev-key, prod-key, ci-key. If one leaks, limited damage.

5. Monitor Usage

Check daily consumption. Spikes = possible leak.


Manage keys at dash.xcrawl.com

Top comments (0)